Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23922

Опубликовано: 18 авг. 2026
Источник: nvd
EPSS Низкий

Описание

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

EPSS

Процентиль: 21%
0.00282
Низкий

Дефекты

CWE-522

Связанные уязвимости

ubuntu
2 дня назад

(The email media OAuth field 'Client secret' cannot be read after savin ...)

debian
2 дня назад

The email media OAuth field 'Client secret' cannot be read after savin ...

github
2 дня назад

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

EPSS

Процентиль: 21%
0.00282
Низкий

Дефекты

CWE-522